An important part of HTTPS Inspection support is the validation of the server's certificates from the signing Certificate Authority (CA).
Note: when HTTPS Categorization (HTTPS Light) is enabled, the trusted CA list is also used.
A Security Gateway with enabled HTTPS Inspection has a built-in predefined list of trusted CAs, based on the Microsoft updated TrustedCA list.
Updates are released based on changes in the recommended CA list.
This article describes how to:
- Perform a manual update of Trusted CAs
- Configure a Security Management Server to check if updates to Trusted CAs are necessary
To configure a Security Management Server to update trust CAs automatically, see sk173629 - How to update trusted CAs automatically.
Performing a manual update of Trusted CAs on a Management Server
-
Download the Trusted CAs package.
Software Subscription or Active Support plan is required to download this package.
-
Upload the Trusted CAs package to the Management Server.
On a Management Server R80 and higher:
Show / Hide this section
-
Connect with SmartConsole to Security Management Server / Domain Management Server.
-
From the left navigation panel, click Manage & Setting.
-
Click Blades.
-
Below Configure HTTPs Inspection, click Configure in SmartDashboard.
-
Click the Trusted CAs section.
-
At the top, click Actions > select Update certificate list... > browse for and select the ZIP file with certificates > click Open.
-
Save the changes and close SmartDashboard.
-
In SmartConsole, install the Access Control Policy on the Security Gateways.
On a Management Server R77.30 and lower:
Show / Hide this section
-
Connect with SmartDashboard to Security Management Server / Domain Management Server.
-
Go to the Application & URL Filtering tab.
-
Expand the Advanced section.
-
Expand the HTTPS Inspection section.
-
Click on the Trusted CAs section.
-
At the top, click Actions button > select Update certificate list... > browse for and selected the ZIP file with certificates > click Open.

-
Install policy on the Security Gateways.
Enabling automatic update checks for Trusted CAs on a Management Server
Note: Updates are only checked automatically. They must be installed manually.
On a Management Server R80 and higher:
Show / Hide this section
-
Connect with SmartConsole to Security Management Server / Domain Management Server.
-
From the left navigation panel, click Manage & Setting.
-
Click Blades.
-
Below Configure HTTPs Inspection, click Configure in SmartDashboard.
-
Click the Trusted CAs section.
-
At the bottom of this page, check the box Notify when a Trusted CA and Blacklist update file is available for installation.
If there is an available update, then this message appears: "A Trusted CA and Blacklist update has been downloaded
"
-
Save the changes and close SmartDashboard.
-
In SmartConsole, install the Access Control Policy on the Security Gateways.
On a Management Server R77.30 and lower:
Show / Hide this section
-
Connect with SmartDashboard to the Security Management Server / Domain Management Server.
-
Go to the Application & URL Filtering tab.
-
Expand the Advanced section.
-
Expand the HTTPS Inspection section.
-
Click the Trusted CAs section.
-
At the bottom of this page, check the box Notify when a Trusted CA and Blacklist update file is available for installation.
If there is an available update, then this message appears: "A Trusted CA and Blacklist update has been downloaded
"
-
Click Install now.
-
Install policy on the Security Gateway.
Related Solutions:
|
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
|